{
  "query": {
    "page": "14"
  },
  "count": 20,
  "total": 46412,
  "page": 14,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T08:45:32.201Z",
    "kev": "2026-10-06T09:44:34.321Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T09:45:34.451Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=14",
    "next": "https://spydr.io/threats.json?page=15"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-105632",
      "url": "https://spydr.io/cve/CVE-2026-105632",
      "published": "2026-10-05T18:17:36.593Z",
      "modified": "2026-10-05T20:17:11.050Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member add themselves to any project in that workspace including network=0 (secret/private) projects they were never invited to and grants them a full Member role (read + write). The resolver checks only workspace-level membership/role and never checks the target project's visibility (network). This collapses project-level tenant isolation within a workspace: a low-privilege member can read and modify confidential data in every private project. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-105631",
      "url": "https://spydr.io/cve/CVE-2026-105631",
      "published": "2026-10-05T18:17:36.427Z",
      "modified": "2026-10-05T18:17:36.557Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-639"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolve FileAsset records within a workspace without checking membership in the asset's project, allowing a workspace member to download assets from private projects when the asset UUID is known. EntityAssetEndpoint.get is a separate public-anchor endpoint that grants AllowAny access and scopes the lookup only to the anchor's workspace rather than its published entity or project. An unauthenticated caller who knows a valid anchor and an asset UUID can therefore retrieve issue-description or comment-description assets belonging to unpublished or private projects in that workspace. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-105630",
      "url": "https://spydr.io/cve/CVE-2026-105630",
      "published": "2026-10-05T18:17:36.250Z",
      "modified": "2026-10-05T19:17:17.093Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-79",
        "CWE-434",
        "CWE-616"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can upload an image/svg+xml file as a generic or issue attachment. The file retains the attacker-controlled Content-Type, and the asset-download endpoint creates a presigned URL with Content-Disposition: inline. In the default self-hosted MinIO deployment, the asset URL is served from the same origin as the Plane application, allowing embedded SVG JavaScript to execute in the application's security context. A victim, including a workspace administrator, who opens the link can have the session compromised through stored XSS, leading to account takeover. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-105629",
      "url": "https://spydr.io/cve/CVE-2026-105629",
      "published": "2026-10-05T18:17:36.087Z",
      "modified": "2026-10-05T18:17:36.207Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-639"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy resolves an estimate point through a bare primary-key lookup without workspace, project, or estimate scoping. An administrator or member of one workspace can permanently delete an estimate point belonging to another workspace by supplying the target UUID in a URL under the attacker's own workspace. This creates a destructive cross-tenant IDOR. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-105628",
      "url": "https://spydr.io/cve/CVE-2026-105628",
      "published": "2026-10-05T18:17:35.917Z",
      "modified": "2026-10-05T18:17:36.050Z",
      "score": 7.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from provider user data through a server-side HTTP request without internal IP validation and follows redirects by default. An attacker can provide an avatar URL that redirects to an internal-only resource, such as a metadata endpoint, and Plane uploads the fetched response as a user avatar file. The object is then exposed through /api/assets/v2/static/{asset_id}/, allowing exfiltration of internally fetched content. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-105385",
      "url": "https://spydr.io/cve/CVE-2026-105385",
      "published": "2026-10-05T18:17:35.740Z",
      "modified": "2026-10-05T18:17:35.740Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "onetwothreeneth"
      ],
      "products": [
        "onetwothreeneth HospitalManagementSystem"
      ],
      "cwes": [
        "CWE-74",
        "CWE-89"
      ],
      "description": "A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this vulnerability is an unknown functionality of the file transaction_details.php. Executing a manipulation of the argument transaction_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105384",
      "url": "https://spydr.io/cve/CVE-2026-105384",
      "published": "2026-10-05T18:17:35.553Z",
      "modified": "2026-10-05T19:17:16.557Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "UNION"
      ],
      "products": [
        "UNION HospitalManagementSystem"
      ],
      "cwes": [
        "CWE-74",
        "CWE-89"
      ],
      "description": "A vulnerability was found in UNION HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected is an unknown function of the file patient_info.php. Performing a manipulation of the argument patient_id results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-104979",
      "url": "https://spydr.io/cve/CVE-2026-104979",
      "published": "2026-10-05T18:17:33.420Z",
      "modified": "2026-10-05T20:17:10.243Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-79",
        "CWE-862"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, including a new user with no workspace memberships, can plant arbitrary HTML in a project that has a published DeployBoard with intake enabled. When a project member or viewer of a closed intake item clicks the planted link, the TipTap \\tjavascript: parser bypass and the target=\"_self\" click handler execute JavaScript in the viewer's session and exfiltrate a long-lived API token. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-104978",
      "url": "https://spydr.io/cve/CVE-2026-104978",
      "published": "2026-10-05T18:17:33.247Z",
      "modified": "2026-10-05T18:17:33.383Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list endpoint is accessible to any authenticated user who knows the workspace slug and project ID, while the public project invitation join endpoint accepts an invitation based only on a submitted email address. When a pending invitation targets an email address that has not registered with Plane, an attacker can enumerate the invitation, register an account using the invited email without mailbox verification, and accept the invitation. The attacker-controlled account is then added to the target workspace and project. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-104977",
      "url": "https://spydr.io/cve/CVE-2026-104977",
      "published": "2026-10-05T18:17:33.080Z",
      "modified": "2026-10-05T19:17:15.790Z",
      "score": 7.7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project member can make the server fetch attacker-selected internal targets, including cloud metadata at 169.254.169.254, and read the response body returned as the link title or favicon. Complete hardening exists on main in PR 9163 but was not included in an earlier released tag. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-104976",
      "url": "https://spydr.io/cve/CVE-2026-104976",
      "published": "2026-10-05T18:17:32.913Z",
      "modified": "2026-10-05T18:17:33.037Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, Plane validates GITEA_HOST only for its URL scheme and does not reject hosts that resolve to private or internal IP addresses. The four outbound requests in the Gitea OAuth flow are derived from this unvalidated host and do not call validate_url(). In addition, avatar_url is taken from the Gitea user's profile, where users can configure external avatar URLs. After an administrator enables Gitea OAuth for a legitimate instance, a Gitea user can set an internal URL as the profile avatar and log in through Gitea, causing Plane to fetch the internal target without validation. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-104975",
      "url": "https://spydr.io/cve/CVE-2026-104975",
      "published": "2026-10-05T18:17:32.747Z",
      "modified": "2026-10-05T19:17:15.657Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-639"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints in plane/app/views/asset/v2.py were remediated for two cross-tenant asset IDORs, CVE-2026-27705 and CVE-2026-46558. Those fixes added a membership check and project_id and workspace__slug scoping to the asset endpoints in that file. The Spaces app in plane/space/views/asset.py serves related public-board operations under /api/public/ but was not remediated. Its EntityAssetEndpoint and AssetRestoreEndpoint resolve a DeployBoard from a public anchor and then read or modify FileAsset rows scoped only to the board's workspace, without a membership check or project_id constraint. An attacker can therefore read, overwrite, or restore assets across projects and workspaces. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-104974",
      "url": "https://spydr.io/cve/CVE-2026-104974",
      "published": "2026-10-05T18:17:32.473Z",
      "modified": "2026-10-05T20:17:10.110Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_active=False can still log in with existing credentials. Successful authentication silently changes is_active back to True, reactivating the account without notifying the administrator. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-104973",
      "url": "https://spydr.io/cve/CVE-2026-104973",
      "published": "2026-10-05T18:17:32.290Z",
      "modified": "2026-10-05T18:17:32.427Z",
      "score": 7.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses only when the webhook is created in apps/api/plane/app/serializers/webhook.py. The delivery task in apps/api/plane/bgtasks/webhook_task.py performs a separate DNS resolution when sending the request and does not validate the resolved IP address, allowing DNS rebinding to bypass the SSRF protection. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-104971",
      "url": "https://spydr.io/cve/CVE-2026-104971",
      "published": "2026-10-05T18:17:32.113Z",
      "modified": "2026-10-05T19:17:15.537Z",
      "score": 8.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "makeplane"
      ],
      "products": [
        "makeplane plane"
      ],
      "cwes": [
        "CWE-639",
        "CWE-862"
      ],
      "description": "Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a source FileAsset without limiting it to the caller's workspace, allowing cross-workspace asset duplication. WorkspaceFileAssetEndpoint and the legacy FileAssetEndpoint omit workspace authorization, allowing authenticated users to read, create, modify, or delete assets in workspaces where they are not members. Separately, WorkspaceViewViewSet.retrieve lacks the authorization decorator used by its sibling actions, exposing an unauthorized workspace-view read surface. This issue is fixed in 1.4.0."
    },
    {
      "id": "CVE-2026-104905",
      "url": "https://spydr.io/cve/CVE-2026-104905",
      "published": "2026-10-05T18:17:31.623Z",
      "modified": "2026-10-05T19:17:15.163Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "NeoRazorX"
      ],
      "products": [
        "NeoRazorX facturascripts"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack."
    },
    {
      "id": "CVE-2026-102576",
      "url": "https://spydr.io/cve/CVE-2026-102576",
      "published": "2026-10-05T18:17:31.200Z",
      "modified": "2026-10-05T18:17:31.200Z",
      "score": 4.2,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "score_source": "redhat.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Red Hat"
      ],
      "products": [
        "Red Hat Quay 3"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "A flaw was found in Quay. A remote attacker could trick a user into logging in through a crafted link, resulting in cross-site scripting (XSS). Because the application does not validate the redirect destination before navigating, this flaw allows the execution of arbitrary script in the context of the victim's authenticated browser session. Successful exploitation requires the target Quay deployment to use direct database authentication and the victim to complete login through the malicious URL."
    },
    {
      "id": "CVE-2026-102295",
      "url": "https://spydr.io/cve/CVE-2026-102295",
      "published": "2026-10-05T18:17:31.057Z",
      "modified": "2026-10-05T19:17:12.340Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "score_source": "redhat.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Red Hat"
      ],
      "products": [
        "Red Hat Quay 3"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "A flaw was found in Quay. A cross-site scripting (XSS) vulnerability in the OAuth callback handler allows a remote attacker to execute arbitrary JavaScript code within a user's browser session. By tricking a logged-in user into visiting a specially crafted link, an attacker can exploit improper input sanitization to run client-side scripts in the application context. Successful exploitation could allow the attacker to compromise the user's session, access sensitive registry information, or perform unauthorized actions on their behalf."
    },
    {
      "id": "CVE-2026-101919",
      "url": "https://spydr.io/cve/CVE-2026-101919",
      "published": "2026-10-05T18:17:30.907Z",
      "modified": "2026-10-05T18:17:30.907Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "redhat.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Red Hat"
      ],
      "products": [
        "Red Hat Multicluster Engine for Kubernetes"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit this vulnerability by supplying a configuration containing unauthorized executable plugins. When downstream controllers consume this configuration, an attacker can achieve arbitrary code execution within the control plane."
    },
    {
      "id": "CVE-2025-15643",
      "url": "https://spydr.io/cve/CVE-2025-15643",
      "published": "2026-10-05T18:17:28.767Z",
      "modified": "2026-10-05T18:17:28.767Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Jose Fernandez"
      ],
      "products": [
        "Jose Fernandez Adsmonetizer"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Fernandez Adsmonetizer adsensei-b30 allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.2.4."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
