{
  "query": {
    "page": "26"
  },
  "count": 20,
  "total": 46877,
  "page": 26,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T18:46:01.823Z",
    "kev": "2026-10-06T19:45:10.728Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T19:46:10.731Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=26",
    "next": "https://spydr.io/threats.json?page=27"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-39760",
      "url": "https://spydr.io/cve/CVE-2026-39760",
      "published": "2026-10-06T06:17:01.087Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00146,
      "epss_percentile": 0.03303,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Creative interactive media"
      ],
      "products": [
        "Creative interactive media Real 3D FlipBook"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions."
    },
    {
      "id": "CVE-2026-39723",
      "url": "https://spydr.io/cve/CVE-2026-39723",
      "published": "2026-10-06T06:17:00.947Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00202,
      "epss_percentile": 0.09175,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Green Invoice"
      ],
      "products": [
        "Green Invoice Morning for WooCommerce"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions."
    },
    {
      "id": "CVE-2026-39599",
      "url": "https://spydr.io/cve/CVE-2026-39599",
      "published": "2026-10-06T06:17:00.803Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 4.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00152,
      "epss_percentile": 0.0377,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "wallstrdev"
      ],
      "products": [
        "wallstrdev WDS MCP Content Manager"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions."
    },
    {
      "id": "CVE-2026-32582",
      "url": "https://spydr.io/cve/CVE-2026-32582",
      "published": "2026-10-06T06:17:00.660Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00174,
      "epss_percentile": 0.06279,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "iatoai"
      ],
      "products": [
        "iatoai IATO MCP"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Contributor Broken Access Control in IATO MCP <= 1.11.0 versions."
    },
    {
      "id": "CVE-2026-32576",
      "url": "https://spydr.io/cve/CVE-2026-32576",
      "published": "2026-10-06T06:17:00.500Z",
      "modified": "2026-10-06T16:17:07.373Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00201,
      "epss_percentile": 0.09051,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "ZWEISCHNEIDER"
      ],
      "products": [
        "ZWEISCHNEIDER Faktur Pro for WooCommerce"
      ],
      "cwes": [
        "CWE-639"
      ],
      "description": "Authorization Bypass Through User-Controlled Key vulnerability in ZWEISCHNEIDER Faktur Pro for WooCommerce woorechnung allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Faktur Pro for WooCommerce: from n/a through 3.2.2."
    },
    {
      "id": "CVE-2026-105775",
      "url": "https://spydr.io/cve/CVE-2026-105775",
      "published": "2026-10-06T06:17:00.280Z",
      "modified": "2026-10-06T15:04:52.637Z",
      "score": 2.1,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.00296,
      "epss_percentile": 0.20331,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "vllm-project"
      ],
      "products": [
        "vllm-project vLLM"
      ],
      "cwes": [
        "CWE-119",
        "CWE-125"
      ],
      "description": "A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105708",
      "url": "https://spydr.io/cve/CVE-2026-105708",
      "published": "2026-10-06T06:17:00.030Z",
      "modified": "2026-10-06T15:04:52.637Z",
      "score": 2.1,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.00273,
      "epss_percentile": 0.17959,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [],
      "products": [
        "imgproxy"
      ],
      "cwes": [
        "CWE-79",
        "CWE-94"
      ],
      "description": "A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105072",
      "url": "https://spydr.io/cve/CVE-2026-105072",
      "published": "2026-10-06T06:16:59.313Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00202,
      "epss_percentile": 0.09176,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "WP Manage Ninja"
      ],
      "products": [
        "WP Manage Ninja FluentBooking Pro"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions."
    },
    {
      "id": "CVE-2026-105707",
      "url": "https://spydr.io/cve/CVE-2026-105707",
      "published": "2026-10-06T05:16:38.177Z",
      "modified": "2026-10-06T18:16:46.097Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.00329,
      "epss_percentile": 0.23816,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [],
      "products": [
        "uptrace"
      ],
      "cwes": [
        "CWE-200",
        "CWE-209"
      ],
      "description": "A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105706",
      "url": "https://spydr.io/cve/CVE-2026-105706",
      "published": "2026-10-06T05:16:38.010Z",
      "modified": "2026-10-06T15:04:52.637Z",
      "score": 2.1,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.00159,
      "epss_percentile": 0.04373,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "SourceCodester"
      ],
      "products": [
        "SourceCodester Drug Recommendation System"
      ],
      "cwes": [
        "CWE-352",
        "CWE-862"
      ],
      "description": "A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks."
    },
    {
      "id": "CVE-2026-105705",
      "url": "https://spydr.io/cve/CVE-2026-105705",
      "published": "2026-10-06T05:16:37.847Z",
      "modified": "2026-10-06T15:04:52.637Z",
      "score": 2.1,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.00273,
      "epss_percentile": 0.17957,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "SourceCodester"
      ],
      "products": [
        "SourceCodester Drug Recommendation System"
      ],
      "cwes": [
        "CWE-79",
        "CWE-94"
      ],
      "description": "A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks."
    },
    {
      "id": "CVE-2026-105704",
      "url": "https://spydr.io/cve/CVE-2026-105704",
      "published": "2026-10-06T05:16:37.663Z",
      "modified": "2026-10-06T15:04:52.637Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.00397,
      "epss_percentile": 0.31689,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "SourceCodester"
      ],
      "products": [
        "SourceCodester Drug Recommendation System"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used."
    },
    {
      "id": "CVE-2026-105703",
      "url": "https://spydr.io/cve/CVE-2026-105703",
      "published": "2026-10-06T04:18:05.587Z",
      "modified": "2026-10-06T18:16:45.953Z",
      "score": 2,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.00227,
      "epss_percentile": 0.12297,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "PHPGurukul"
      ],
      "products": [
        "PHPGurukul User Registration & Login and User Management System"
      ],
      "cwes": [
        "CWE-285",
        "CWE-863"
      ],
      "description": "A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect authorization. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized."
    },
    {
      "id": "CVE-2026-105621",
      "url": "https://spydr.io/cve/CVE-2026-105621",
      "published": "2026-10-06T04:18:05.360Z",
      "modified": "2026-10-06T14:17:37.943Z",
      "score": 2.1,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.0023,
      "epss_percentile": 0.12597,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "jishenghua"
      ],
      "products": [
        "jishenghua jshERP"
      ],
      "cwes": [
        "CWE-266",
        "CWE-285"
      ],
      "description": "A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105611",
      "url": "https://spydr.io/cve/CVE-2026-105611",
      "published": "2026-10-06T04:17:58.950Z",
      "modified": "2026-10-06T04:18:05.067Z",
      "score": 2,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.0024,
      "epss_percentile": 0.13851,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "chillzhuang"
      ],
      "products": [
        "chillzhuang SpringBlade"
      ],
      "cwes": [
        "CWE-266",
        "CWE-285"
      ],
      "description": "A vulnerability was determined in chillzhuang SpringBlade up to 5.0.1. This affects an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/RoleController.java of the component User Detail Endpoint. This manipulation of the argument ID causes improper authorization. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105610",
      "url": "https://spydr.io/cve/CVE-2026-105610",
      "published": "2026-10-06T03:17:01.237Z",
      "modified": "2026-10-06T13:16:45.657Z",
      "score": 2,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.00227,
      "epss_percentile": 0.12297,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "chillzhuang"
      ],
      "products": [
        "chillzhuang SpringBlade"
      ],
      "cwes": [
        "CWE-266",
        "CWE-285"
      ],
      "description": "A vulnerability was found in chillzhuang SpringBlade up to 5.0.1. The impacted element is an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/ParamController.java of the component Parameter Submit Management. The manipulation of the argument initPassword results in improper authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105573",
      "url": "https://spydr.io/cve/CVE-2026-105573",
      "published": "2026-10-06T03:17:01.033Z",
      "modified": "2026-10-06T18:16:45.803Z",
      "score": 2.1,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.00229,
      "epss_percentile": 0.12544,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "newbee-ltd"
      ],
      "products": [
        "newbee-ltd newbee-mall"
      ],
      "cwes": [
        "CWE-840"
      ],
      "description": "A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity Handler. Performing a manipulation of the argument goodsCount results in business logic errors. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105572",
      "url": "https://spydr.io/cve/CVE-2026-105572",
      "published": "2026-10-06T03:17:00.827Z",
      "modified": "2026-10-06T15:04:52.637Z",
      "score": 2.1,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.00223,
      "epss_percentile": 0.11768,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [],
      "products": [
        "PickMall Lilishop"
      ],
      "cwes": [
        "CWE-285",
        "CWE-639"
      ],
      "description": "A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects an unknown function of the file /buyer/trade/receipt of the component Buyer Invoice List. Such manipulation of the argument memberId leads to authorization bypass. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105571",
      "url": "https://spydr.io/cve/CVE-2026-105571",
      "published": "2026-10-06T02:17:04.613Z",
      "modified": "2026-10-06T15:04:52.637Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.00278,
      "epss_percentile": 0.18503,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [],
      "products": [
        "PickMall Lilishop"
      ],
      "cwes": [
        "CWE-266",
        "CWE-285"
      ],
      "description": "A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105487",
      "url": "https://spydr.io/cve/CVE-2026-105487",
      "published": "2026-10-06T02:17:04.403Z",
      "modified": "2026-10-06T13:16:45.150Z",
      "score": 2.1,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.01089,
      "epss_percentile": 0.64238,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "yogeshojha"
      ],
      "products": [
        "yogeshojha reNgine"
      ],
      "cwes": [
        "CWE-77",
        "CWE-78"
      ],
      "description": "A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component listTargets Endpoint. The manipulation of the argument Name results in os command injection. The attack can be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
