{
  "query": {
    "page": "3"
  },
  "count": 20,
  "total": 46338,
  "page": 3,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T00:45:13.875Z",
    "kev": "2026-10-06T00:44:13.530Z",
    "epss": "2026-10-06T00:57:13.818Z",
    "breaches": "2026-10-06T00:45:13.561Z",
    "posts": "2026-10-06T00:45:13.875Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=3",
    "next": "https://spydr.io/threats.json?page=4"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-103433",
      "url": "https://spydr.io/cve/CVE-2026-103433",
      "published": "2026-10-05T22:16:56.370Z",
      "modified": "2026-10-05T22:16:56.370Z",
      "score": 6.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "docker.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Docker"
      ],
      "products": [
        "Docker Buildx"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpreted as a client-side pathname, or consume a local OCI image layout outside the project after entitlement validation checks a different path representation. Users who run untrusted Bake definitions are affected."
    },
    {
      "id": "CVE-2026-0482",
      "url": "https://spydr.io/cve/CVE-2026-0482",
      "published": "2026-10-05T22:16:56.210Z",
      "modified": "2026-10-05T22:16:56.210Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "amd.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "AMD"
      ],
      "products": [
        "AMD Alveo™ Accelerator Cards",
        "AMD Versal™ Prime Series Adaptive SoCs",
        "AMD Versal™ Premium Series Adaptive SoCs",
        "AMD Versal™ AI Edge Series Adaptive SoCs",
        "AMD Versal™ AI Core Series Adaptive SoCs",
        "AMD Versal™ HBM Series Adaptive SoCs",
        "AMD Versal™ RF Series Adaptive SoCs",
        "AMD Versal Premium Series Gen 2 Adaptive SOCs (2VP3402, 2VP3502, 2VP3602)"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "In AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot mode—when enabled through board modifications—could allow crafted images to trigger a buffer overflow and overwrite an active function pointer, which may result in arbitrary code execution during boot process. This condition could lead to potential impacts on confidentiality, integrity, and availability."
    },
    {
      "id": "CVE-2026-0461",
      "url": "https://spydr.io/cve/CVE-2026-0461",
      "published": "2026-10-05T22:16:55.280Z",
      "modified": "2026-10-05T22:16:55.280Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "amd.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "AMD"
      ],
      "products": [
        "AMD Zynq™ UltraScale+ MPSoCs",
        "AMD Zynq™ UltraScale+ RFSoCs",
        "AMD Kria SOMs"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow the DDR receive buffer into FSBL memory, potentially resulting in unauthorized code execution during the boot process. This issue could impact the confidentiality, integrity, or availability of affected system."
    },
    {
      "id": "CVE-2026-93326",
      "url": "https://spydr.io/cve/CVE-2026-93326",
      "published": "2026-10-05T21:16:37.907Z",
      "modified": "2026-10-05T21:16:37.907Z",
      "score": 6,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "docker.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "moby"
      ],
      "products": [
        "moby BuildKit"
      ],
      "cwes": [
        "CWE-180"
      ],
      "description": "A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definition can make the repository look like it is coming from a different remote URL than it really is when Git clone is happening. If policy is doing more stricter validation, for example based on commit SHA, commit data, or signatures, then all these validations still apply correctly."
    },
    {
      "id": "CVE-2026-84900",
      "url": "https://spydr.io/cve/CVE-2026-84900",
      "published": "2026-10-05T21:16:37.747Z",
      "modified": "2026-10-05T21:16:37.747Z",
      "score": 6.8,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "hp.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "HP Inc"
      ],
      "products": [
        "HP Inc ThinPro 8.1",
        "HP Inc ThinPro 9"
      ],
      "cwes": [
        "CWE-354"
      ],
      "description": "Previous versions of HP ThinPro (prior to HP ThinPro 8.1 SP10) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.1 SP10, which includes updates to mitigate potential vulnerabilities. Previous versions of HP ThinPro (prior to HP ThinPro 9 SP3) could potentially contain security vulnerabilities. HP has released HP ThinPro 9 SP3, which includes updates to mitigate potential vulnerabilities."
    },
    {
      "id": "CVE-2026-77226",
      "url": "https://spydr.io/cve/CVE-2026-77226",
      "published": "2026-10-05T21:16:37.337Z",
      "modified": "2026-10-05T21:16:37.337Z",
      "score": 9.2,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Camunda"
      ],
      "products": [
        "Camunda 7"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-create endpoint and create a new administrator account when the camunda-admin group is empty but the system is fully administered, resulting in account takeover and potential process deployment or script execution as the engine's service user."
    },
    {
      "id": "CVE-2026-105773",
      "url": "https://spydr.io/cve/CVE-2026-105773",
      "published": "2026-10-05T21:16:36.093Z",
      "modified": "2026-10-05T21:16:36.093Z",
      "score": 7.3,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "Canimaan Software"
      ],
      "products": [
        "Canimaan Software ClamXAV"
      ],
      "cwes": [
        "CWE-362"
      ],
      "description": "Canimaan Software ClamXAV versions 3.3 - 3.11 contains a local privilege escalation vulnerability in the Privileged Helper Tool caused by a race condition and insufficient file validation, allowing a local attacker to execute arbitrary code with system privileges. Fixed in 3.11.1."
    },
    {
      "id": "CVE-2026-105768",
      "url": "https://spydr.io/cve/CVE-2026-105768",
      "published": "2026-10-05T21:16:35.913Z",
      "modified": "2026-10-05T21:16:36.027Z",
      "score": 6.3,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "chainguard-dev"
      ],
      "products": [
        "chainguard-dev apko"
      ],
      "cwes": [
        "CWE-197"
      ],
      "description": "apko allows users to build and publish OCI container images built from apk packages. From version 0.2.0 to before version 1.4.5, UserEntry.Parse and GroupEntry.Parse in pkg/passwd read the UID and GID fields of /etc/passwd and /etc/group entries with strconv.Atoi and convert them to uint32 without a range check. On 64-bit platforms an out-of-range value such as 4294967296 (2^32) is truncated to 0, and negative values wrap. Because apko parses the passwd and group entries supplied by the packages it installs and writes them back into the image, an attacker who controls a package installed into the image can ship an entry that appears to declare an unprivileged UID or GID but is written into the built image as UID 0 or GID 0 (root). The truncated UID is also used when resolving the image's run-as user. This issue has been fixed in version 1.4.5."
    },
    {
      "id": "CVE-2026-105741",
      "url": "https://spydr.io/cve/CVE-2026-105741",
      "published": "2026-10-05T21:16:35.740Z",
      "modified": "2026-10-05T21:16:35.740Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "langflow-ai"
      ],
      "products": [
        "langflow-ai langflow"
      ],
      "cwes": [
        "CWE-290",
        "CWE-345"
      ],
      "description": "Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the \"local-only\" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an attacker could make the server treat the request as originating from localhost, letting them write/overwrite an MCP client configuration file on the server's filesystem. This vulnerability is fixed in 1.10.3."
    },
    {
      "id": "CVE-2026-105740",
      "url": "https://spydr.io/cve/CVE-2026-105740",
      "published": "2026-10-05T21:16:35.567Z",
      "modified": "2026-10-05T21:16:35.567Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "langflow-ai"
      ],
      "products": [
        "langflow-ai langflow"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the \"Stdio\" transport. The user-supplied command field is passed directly to bash -c \"exec {command}\" with zero validation, no allowlisting, and no sandboxing. The command executes immediately when the server list is fetched. Additionally, the env field allows arbitrary environment variable injection (e.g., LD_PRELOAD, PATH override). This vulnerability is fixed in 1.9.0."
    },
    {
      "id": "CVE-2026-105699",
      "url": "https://spydr.io/cve/CVE-2026-105699",
      "published": "2026-10-05T21:16:35.410Z",
      "modified": "2026-10-05T21:16:35.410Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "langflow-ai"
      ],
      "products": [
        "langflow-ai langflow"
      ],
      "cwes": [
        "CWE-639"
      ],
      "description": "Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.6.8 until 1.9.1, Langflow authenticated access to the project identifier in a project-scoped MCP connection but did not authorize the resource URI supplied to resources/read. read_resource forwarded the attacker-controlled URI to handle_read_resource, which parsed a flow_id and filename and called storage_service.get_file without verifying that the flow belonged to the authenticated user or current project. A user with access to any project-scoped MCP endpoint could therefore request another user's flow-backed file, while global handle_list_resources and handle_list_tools behavior could disclose flow and file identifiers that made targeting easier. The vulnerability disclosed uploaded documents, structured data, prompts, and other private flow artifacts across tenants but did not modify victim files or stored flows. This issue is fixed in version 1.9.1."
    },
    {
      "id": "CVE-2026-105698",
      "url": "https://spydr.io/cve/CVE-2026-105698",
      "published": "2026-10-05T21:16:35.257Z",
      "modified": "2026-10-05T21:16:35.257Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "langflow-ai"
      ],
      "products": [
        "langflow-ai langflow",
        "langflow-ai langflow-base"
      ],
      "cwes": [
        "CWE-639",
        "CWE-862"
      ],
      "description": "Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} handlers. Through version 1.7.1, an unauthenticated caller who knew another user's flow UUID could reach these handlers; from version 1.7.2 through 1.10.0, callers had to authenticate but needed no elevated privileges. Such a caller could cause retrieve_vertices_order to load and cache the private graph, enumerate its vertex identifiers, and use build_vertex to execute selected vertices and receive their results. build_graph_from_db_no_cache performed a primary-key lookup without an owner filter. This could disclose private flow structure, configured values, and selected outputs and could trigger victim-configured side effects and build-history records, although it did not expose the victim's variable-store credentials or permit modification of the stored flow. This issue is fixed in Langflow 1.10.1 and langflow-base 0.10.1."
    },
    {
      "id": "CVE-2026-105697",
      "url": "https://spydr.io/cve/CVE-2026-105697",
      "published": "2026-10-05T21:16:35.087Z",
      "modified": "2026-10-05T21:16:35.087Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "github.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "langflow-ai"
      ],
      "products": [
        "langflow-ai langflow",
        "langflow-ai langflow-base",
        "langflow-ai lfx"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c \"exec {command} ...\". Any user able to reach the MCP server settings (\"Settings → MCP Servers → Add MCP Server\", POST/PATCH /api/v2/mcp/servers/{server_name}) or to build a flow with the MCP Tools component could add a \"server\" whose command is an arbitrary OS command (touch, rm -rf, a reverse shell, ...). The command runs on the Langflow host as the Langflow process user as soon as Langflow tries to connect to the server (listing servers, loading tools, running the flow) — even when the UI then reports that the stdio server failed to start. With the default LANGFLOW_AUTO_LOGIN=true, GET /api/v1/auto_login hands out a token without credentials, so on an exposed instance running the default configuration this is reachable without an account. AUTO_LOGIN is documented as a development-only setting; with it disabled, any authenticated (non-admin) user can exploit it. This issue is fixed in Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3."
    },
    {
      "id": "CVE-2026-105447",
      "url": "https://spydr.io/cve/CVE-2026-105447",
      "published": "2026-10-05T21:16:34.650Z",
      "modified": "2026-10-05T21:16:34.650Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N",
      "score_source": "redhat.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Red Hat"
      ],
      "products": [
        "Red Hat Quay 3"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with read-only privileges can exploit this flaw by querying the build trigger API to retrieve these delegate tokens. This issue allows a restricted user to bypass read-only limitations and push arbitrary container images to private repositories, leading to privilege escalation."
    },
    {
      "id": "CVE-2026-105444",
      "url": "https://spydr.io/cve/CVE-2026-105444",
      "published": "2026-10-05T21:16:34.470Z",
      "modified": "2026-10-05T21:16:34.470Z",
      "score": 2.1,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "dotnet"
      ],
      "products": [
        "dotnet eShop"
      ],
      "cwes": [
        "CWE-99"
      ],
      "description": "A security flaw has been discovered in dotnet eShop .NET 8. The impacted element is the function GetOrderAsync of the file src/Ordering.API/Apis/OrdersApi.cs of the component Ordering API. Performing a manipulation of the argument OrderNumber results in improper control of resource identifiers. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105438",
      "url": "https://spydr.io/cve/CVE-2026-105438",
      "published": "2026-10-05T21:16:34.297Z",
      "modified": "2026-10-05T21:16:34.297Z",
      "score": 2.1,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [],
      "products": [
        "O2OA"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "A flaw has been found in O2OA up to 10.0.1-ce. This affects the function ActionUploadExcelWithUrl of the file /x_general_assemble_control/jaxrs/excel/upload/with/url of the component General Module. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-102262",
      "url": "https://spydr.io/cve/CVE-2026-102262",
      "published": "2026-10-05T21:16:32.400Z",
      "modified": "2026-10-05T21:16:32.400Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "Newell Brands"
      ],
      "products": [
        "Newell Brands DYMO ID"
      ],
      "cwes": [
        "CWE-22",
        "CWE-668"
      ],
      "description": "Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0."
    },
    {
      "id": "CVE-2026-101893",
      "url": "https://spydr.io/cve/CVE-2026-101893",
      "published": "2026-10-05T21:16:32.227Z",
      "modified": "2026-10-05T21:16:32.227Z",
      "score": 5.1,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "Newell Brands"
      ],
      "products": [
        "Newell Brands DYMO ID"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "Newell Brands DYMO ID 1.5.1.71 parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files view automatically parses every recognized job file extension on folder browse. A crafted file on any browsed network share can perform SSRF, capture NTLMv2 credentials, read local files, or crash the process. Fixed in 1.6.0."
    },
    {
      "id": "CVE-2026-97257",
      "url": "https://spydr.io/cve/CVE-2026-97257",
      "published": "2026-10-05T20:17:29.447Z",
      "modified": "2026-10-05T20:17:29.447Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "PressTigers"
      ],
      "products": [
        "PressTigers Simple Event Planner"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7."
    },
    {
      "id": "CVE-2026-95265",
      "url": "https://spydr.io/cve/CVE-2026-95265",
      "published": "2026-10-05T20:17:29.313Z",
      "modified": "2026-10-05T20:17:29.313Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [],
      "products": [],
      "cwes": [],
      "description": "Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor catchimage endpoint. The private-IP validation does not block loopback or link-local addresses, allowing an attacker to make the server probe internal HTTP services through response differences."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
