{
  "query": {
    "page": "17"
  },
  "count": 20,
  "total": 46749,
  "page": 17,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T10:45:36.976Z",
    "kev": "2026-10-06T11:44:39.558Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T11:45:39.554Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=17",
    "next": "https://spydr.io/threats.json?page=18"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-105057",
      "url": "https://spydr.io/cve/CVE-2026-105057",
      "published": "2026-10-06T09:17:40.133Z",
      "modified": "2026-10-06T09:17:40.133Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Ben Marshall"
      ],
      "products": [
        "Ben Marshall Zero Spam"
      ],
      "cwes": [
        "CWE-290"
      ],
      "description": "Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions."
    },
    {
      "id": "CVE-2026-104814",
      "url": "https://spydr.io/cve/CVE-2026-104814",
      "published": "2026-10-06T09:17:39.973Z",
      "modified": "2026-10-06T09:17:39.973Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "epiphyt"
      ],
      "products": [
        "epiphyt Form Block"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions."
    },
    {
      "id": "CVE-2026-104757",
      "url": "https://spydr.io/cve/CVE-2026-104757",
      "published": "2026-10-06T09:17:39.810Z",
      "modified": "2026-10-06T09:17:39.810Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Javier Carazo"
      ],
      "products": [
        "Javier Carazo Import and export users and customers"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions."
    },
    {
      "id": "CVE-2026-104747",
      "url": "https://spydr.io/cve/CVE-2026-104747",
      "published": "2026-10-06T09:17:39.643Z",
      "modified": "2026-10-06T09:17:39.643Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Edge-Themes"
      ],
      "products": [
        "Edge-Themes Haaken"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Unauthenticated PHP Object Injection in Haaken <= 1.5 versions."
    },
    {
      "id": "CVE-2026-104672",
      "url": "https://spydr.io/cve/CVE-2026-104672",
      "published": "2026-10-06T09:17:39.483Z",
      "modified": "2026-10-06T09:17:39.483Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Nexcess"
      ],
      "products": [
        "Nexcess GiveWP"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.17.0 versions."
    },
    {
      "id": "CVE-2026-104670",
      "url": "https://spydr.io/cve/CVE-2026-104670",
      "published": "2026-10-06T09:17:39.317Z",
      "modified": "2026-10-06T09:17:39.317Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "ThimPress"
      ],
      "products": [
        "ThimPress LearnPress"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions."
    },
    {
      "id": "CVE-2026-104406",
      "url": "https://spydr.io/cve/CVE-2026-104406",
      "published": "2026-10-06T09:17:39.163Z",
      "modified": "2026-10-06T09:17:39.163Z",
      "score": 7.3,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "picu"
      ],
      "products": [
        "picu"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in picu <= 3.10.1 versions."
    },
    {
      "id": "CVE-2026-104405",
      "url": "https://spydr.io/cve/CVE-2026-104405",
      "published": "2026-10-06T09:17:39.013Z",
      "modified": "2026-10-06T09:17:39.013Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Nexcess"
      ],
      "products": [
        "Nexcess GiveWP"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions."
    },
    {
      "id": "CVE-2026-104399",
      "url": "https://spydr.io/cve/CVE-2026-104399",
      "published": "2026-10-06T09:17:38.860Z",
      "modified": "2026-10-06T09:17:38.860Z",
      "score": 6.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "StylemixThemes"
      ],
      "products": [
        "StylemixThemes Motors"
      ],
      "cwes": [
        "CWE-201"
      ],
      "description": "Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124."
    },
    {
      "id": "CVE-2026-104395",
      "url": "https://spydr.io/cve/CVE-2026-104395",
      "published": "2026-10-06T09:17:38.570Z",
      "modified": "2026-10-06T09:17:38.570Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "picu"
      ],
      "products": [
        "picu"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions."
    },
    {
      "id": "CVE-2026-104394",
      "url": "https://spydr.io/cve/CVE-2026-104394",
      "published": "2026-10-06T09:17:38.230Z",
      "modified": "2026-10-06T09:17:38.230Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Syed Balkhi"
      ],
      "products": [
        "Syed Balkhi Charitable"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions."
    },
    {
      "id": "CVE-2026-104387",
      "url": "https://spydr.io/cve/CVE-2026-104387",
      "published": "2026-10-06T09:17:38.077Z",
      "modified": "2026-10-06T09:17:38.077Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "blubrry"
      ],
      "products": [
        "blubrry PowerPress Podcasting"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions."
    },
    {
      "id": "CVE-2026-104385",
      "url": "https://spydr.io/cve/CVE-2026-104385",
      "published": "2026-10-06T09:17:37.917Z",
      "modified": "2026-10-06T09:17:37.917Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Adrian Tobey"
      ],
      "products": [
        "Adrian Tobey Groundhogg"
      ],
      "cwes": [
        "CWE-201"
      ],
      "description": "Unauthenticated Sensitive Data Exposure in Groundhogg <= 4.8.3 versions."
    },
    {
      "id": "CVE-2026-103346",
      "url": "https://spydr.io/cve/CVE-2026-103346",
      "published": "2026-10-06T09:17:37.760Z",
      "modified": "2026-10-06T09:17:37.760Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Tomlister"
      ],
      "products": [
        "Tomlister Payflex Payment Gateway"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1."
    },
    {
      "id": "CVE-2026-102915",
      "url": "https://spydr.io/cve/CVE-2026-102915",
      "published": "2026-10-06T09:17:37.617Z",
      "modified": "2026-10-06T09:17:37.617Z",
      "score": 8.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Marco van Wieren"
      ],
      "products": [
        "Marco van Wieren WPO365"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Subscriber Broken Access Control in WPO365 <= 44.1 versions."
    },
    {
      "id": "CVE-2026-102387",
      "url": "https://spydr.io/cve/CVE-2026-102387",
      "published": "2026-10-06T09:17:37.463Z",
      "modified": "2026-10-06T09:17:37.463Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "XServer"
      ],
      "products": [
        "Xserver Migrator"
      ],
      "cwes": [
        "CWE-497"
      ],
      "description": "Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions."
    },
    {
      "id": "CVE-2026-100518",
      "url": "https://spydr.io/cve/CVE-2026-100518",
      "published": "2026-10-06T09:17:37.283Z",
      "modified": "2026-10-06T09:17:37.283Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "WebFactory"
      ],
      "products": [
        "WebFactory Advanced Google reCAPTCHA"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions."
    },
    {
      "id": "CVE-2026-85153",
      "url": "https://spydr.io/cve/CVE-2026-85153",
      "published": "2026-10-06T08:16:37.227Z",
      "modified": "2026-10-06T08:16:37.227Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "cert-in.org.in",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Schmooze"
      ],
      "products": [
        "Schmooze dating mobile Application"
      ],
      "cwes": [
        "CWE-321"
      ],
      "description": "This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to backend and cloud resources and forge client requests on the targeted system."
    },
    {
      "id": "CVE-2026-105807",
      "url": "https://spydr.io/cve/CVE-2026-105807",
      "published": "2026-10-06T08:16:36.840Z",
      "modified": "2026-10-06T08:16:36.840Z",
      "score": 6.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "SourceCodester"
      ],
      "products": [
        "SourceCodester Simple Student Information System"
      ],
      "cwes": [
        "CWE-74",
        "CWE-89"
      ],
      "description": "A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in sql injection. The attack can be initiated remotely."
    },
    {
      "id": "CVE-2026-105305",
      "url": "https://spydr.io/cve/CVE-2026-105305",
      "published": "2026-10-06T08:16:35.697Z",
      "modified": "2026-10-06T08:16:35.697Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "redhat.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Red Hat"
      ],
      "products": [
        "Red Hat Build of Keycloak",
        "Red Hat Single Sign-On 7"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "A flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities to obtain security tokens. The issue occurs because the flow fails to check the minimum authentication level required by a client configuration. This allows an attacker who has stolen a user's password to bypass mandatory multi-factor authentication and gain unauthorized access to the Keycloak Admin REST API."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
