{
  "query": {
    "page": "13"
  },
  "count": 20,
  "total": 46412,
  "page": 13,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T08:45:32.201Z",
    "kev": "2026-10-06T08:44:32.120Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T08:45:32.201Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=13",
    "next": "https://spydr.io/threats.json?page=14"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-104711",
      "url": "https://spydr.io/cve/CVE-2026-104711",
      "published": "2026-10-05T19:17:14.497Z",
      "modified": "2026-10-05T20:17:08.790Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Struts"
      ],
      "cwes": [
        "CWE-917"
      ],
      "description": "Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts 7 is affected only when the OGNL allowlist is disabled; it is enabled by default. Applications using the default action mapper, the restful2 mapper, or the Struts REST plugin are not affected. This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue."
    },
    {
      "id": "CVE-2026-103352",
      "url": "https://spydr.io/cve/CVE-2026-103352",
      "published": "2026-10-05T19:17:13.847Z",
      "modified": "2026-10-05T19:17:13.847Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "WP BASE"
      ],
      "products": [
        "WP BASE Booking"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0."
    },
    {
      "id": "CVE-2026-103349",
      "url": "https://spydr.io/cve/CVE-2026-103349",
      "published": "2026-10-05T19:17:13.703Z",
      "modified": "2026-10-05T19:17:13.703Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Rymera Web Co"
      ],
      "products": [
        "Rymera Web Co Product Feed PRO for WooCommerce"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data vulnerability in Rymera Web Co Product Feed PRO for WooCommerce woo-product-feed-pro allows Object Injection.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.5.7."
    },
    {
      "id": "CVE-2026-103334",
      "url": "https://spydr.io/cve/CVE-2026-103334",
      "published": "2026-10-05T19:17:13.543Z",
      "modified": "2026-10-05T19:17:13.543Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Etoile Web Design Incorporated"
      ],
      "products": [
        "Etoile Web Design Incorporated Five Star Restaurant Reservations"
      ],
      "cwes": [
        "CWE-201"
      ],
      "description": "Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.24."
    },
    {
      "id": "CVE-2026-103086",
      "url": "https://spydr.io/cve/CVE-2026-103086",
      "published": "2026-10-05T19:17:13.403Z",
      "modified": "2026-10-05T19:17:13.403Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Stiofan"
      ],
      "products": [
        "Stiofan UsersWP"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.74."
    },
    {
      "id": "CVE-2026-103085",
      "url": "https://spydr.io/cve/CVE-2026-103085",
      "published": "2026-10-05T19:17:13.240Z",
      "modified": "2026-10-05T19:17:13.240Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "WP User Manager"
      ],
      "products": [
        "WP User Manager"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20."
    },
    {
      "id": "CVE-2026-102383",
      "url": "https://spydr.io/cve/CVE-2026-102383",
      "published": "2026-10-05T19:17:12.457Z",
      "modified": "2026-10-05T19:17:12.457Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "VillaTheme"
      ],
      "products": [
        "VillaTheme Lookzy"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Missing Authorization vulnerability in VillaTheme Lookzy woo-lookbook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lookzy: from n/a through 1.1.14."
    },
    {
      "id": "CVE-2026-100515",
      "url": "https://spydr.io/cve/CVE-2026-100515",
      "published": "2026-10-05T19:17:12.200Z",
      "modified": "2026-10-05T19:17:12.200Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "VillaTheme"
      ],
      "products": [
        "VillaTheme Photo Reviews for WooCommerce"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30."
    },
    {
      "id": "CVE-2026-100509",
      "url": "https://spydr.io/cve/CVE-2026-100509",
      "published": "2026-10-05T19:17:12.047Z",
      "modified": "2026-10-05T19:17:12.047Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Webful Creations"
      ],
      "products": [
        "Webful Creations RepairBuddy"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Stored XSS.This issue affects RepairBuddy: from n/a through 4.1225."
    },
    {
      "id": "CVE-2026-93323",
      "url": "https://spydr.io/cve/CVE-2026-93323",
      "published": "2026-10-05T18:17:39.630Z",
      "modified": "2026-10-05T19:17:26.403Z",
      "score": 6.8,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "docker.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "moby"
      ],
      "products": [
        "moby BuildKit"
      ],
      "cwes": [
        "CWE-789"
      ],
      "description": "The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB."
    },
    {
      "id": "CVE-2026-93322",
      "url": "https://spydr.io/cve/CVE-2026-93322",
      "published": "2026-10-05T18:17:39.490Z",
      "modified": "2026-10-05T19:17:26.290Z",
      "score": 6.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "docker.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "moby"
      ],
      "products": [
        "moby BuildKit"
      ],
      "cwes": [
        "CWE-129"
      ],
      "description": "A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon."
    },
    {
      "id": "CVE-2026-93320",
      "url": "https://spydr.io/cve/CVE-2026-93320",
      "published": "2026-10-05T18:17:38.353Z",
      "modified": "2026-10-05T19:17:26.177Z",
      "score": 6,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "docker.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "moby"
      ],
      "products": [
        "moby BuildKit"
      ],
      "cwes": [
        "CWE-441"
      ],
      "description": "BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access."
    },
    {
      "id": "CVE-2026-93319",
      "url": "https://spydr.io/cve/CVE-2026-93319",
      "published": "2026-10-05T18:17:38.217Z",
      "modified": "2026-10-05T20:17:28.410Z",
      "score": 5.7,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "docker.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "moby"
      ],
      "products": [
        "moby BuildKit"
      ],
      "cwes": [
        "CWE-567"
      ],
      "description": "A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic."
    },
    {
      "id": "CVE-2026-93318",
      "url": "https://spydr.io/cve/CVE-2026-93318",
      "published": "2026-10-05T18:17:38.080Z",
      "modified": "2026-10-05T20:17:28.260Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "docker.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "moby"
      ],
      "products": [
        "moby BuildKit"
      ],
      "cwes": [
        "CWE-354"
      ],
      "description": "A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents. If a BuildKit daemon with shared or persistent cache first processes such a malicious image, a later build using the victim image may mount the attacker-controlled layer contents as the base image. This can allow code from the malicious image to run in the victim build, for example by replacing a commonly executed path such as /bin/sh. The attacker-controlled code may read build secrets mounted into the build, access other build resources, alter output artifacts, or hang the build. The issue affects both regular snapshotters and lazy-pulling snapshotters such as stargz."
    },
    {
      "id": "CVE-2026-93317",
      "url": "https://spydr.io/cve/CVE-2026-93317",
      "published": "2026-10-05T18:17:37.923Z",
      "modified": "2026-10-05T20:17:28.127Z",
      "score": 5.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "docker.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "moby"
      ],
      "products": [
        "moby BuildKit"
      ],
      "cwes": [
        "CWE-354"
      ],
      "description": "An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity."
    },
    {
      "id": "CVE-2026-93316",
      "url": "https://spydr.io/cve/CVE-2026-93316",
      "published": "2026-10-05T18:17:37.780Z",
      "modified": "2026-10-05T20:17:27.983Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "docker.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "moby"
      ],
      "products": [
        "moby BuildKit"
      ],
      "cwes": [
        "CWE-476"
      ],
      "description": "If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident."
    },
    {
      "id": "CVE-2026-78413",
      "url": "https://spydr.io/cve/CVE-2026-78413",
      "published": "2026-10-05T18:17:37.383Z",
      "modified": "2026-10-05T20:17:27.143Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L",
      "score_source": "rapid7.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Rapid7"
      ],
      "products": [
        "Rapid7 Velociraptor"
      ],
      "cwes": [
        "CWE-276"
      ],
      "description": "Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions like EXECVE to launch. The `Windows.Sysinternals.SysmonLogForward` is a monitoring artifact used to forward sysmon events to the server. The artifact allows the user to specify an arbitrary binary path as a parameter, and did not enforce an additional required permission, allowing users with COLLECT_CLIENT permissions (normally given by the \"Investigator\" role) to collect it from endpoints and run a different binary program than the installed sysmon binary. To successfully exploit this vulnerability the user must already have access to collect artifacts from the endpoint (i.e. have the COLLECT_CLIENT given typically by the \"Investigator\" role)."
    },
    {
      "id": "CVE-2026-78411",
      "url": "https://spydr.io/cve/CVE-2026-78411",
      "published": "2026-10-05T18:17:37.257Z",
      "modified": "2026-10-05T20:17:26.883Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "rapid7.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Rapid7"
      ],
      "products": [
        "Rapid7 Velociraptor"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata. Server metadata is often used to store site wide configuration data that should only be updated by the server admin."
    },
    {
      "id": "CVE-2026-42700",
      "url": "https://spydr.io/cve/CVE-2026-42700",
      "published": "2026-10-05T18:17:36.940Z",
      "modified": "2026-10-05T18:17:36.940Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "GhozyLab"
      ],
      "products": [
        "GhozyLab Image Slider Widget"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Image Slider Widget image-slider-widget allows Stored XSS.This issue affects Image Slider Widget: from n/a through 1.1.130."
    },
    {
      "id": "CVE-2026-105633",
      "url": "https://spydr.io/cve/CVE-2026-105633",
      "published": "2026-10-05T18:17:36.757Z",
      "modified": "2026-10-05T19:17:17.213Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-639"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpoint accepts issue_id in the URL but omits it from the database query. A project member can use an issue_id they control in the URL while targeting another user's attachment by its pk UUID. Because the server matches only pk, workspace, and project_id, it modifies the attachment regardless of the issue_id in the URL. When the attachment is pending and has not been confirmed as uploaded, the PATCH handler sets created_by = request.user and transfers attachment ownership to the attacker. This issue is fixed in 1.4.0."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
