{
  "query": {
    "page": "58"
  },
  "count": 20,
  "total": 47687,
  "page": 58,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T00:48:40.801Z",
    "kev": "2026-10-08T01:49:42.842Z",
    "epss": "2026-10-08T01:00:40.923Z",
    "breaches": "2026-10-08T00:48:40.536Z",
    "posts": "2026-10-08T01:48:43.051Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=58",
    "next": "https://spydr.io/threats.json?page=59"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-98173",
      "url": "https://spydr.io/cve/CVE-2026-98173",
      "published": "2026-10-06T09:17:59.060Z",
      "modified": "2026-10-07T07:17:03.737Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.00325,
      "epss_percentile": 0.23557,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free of iface in cifs_try_adding_channels() cifs_try_adding_channels() iterates ses->iface_list with list_for_each_entry_safe_from(), which captures the next entry (niface) under iface_lock. The loop body then drops iface_lock for the whole duration of cifs_ses_add_channel(). A concurrent interface refresh (SMB3_request_interfaces() -> parse_server_interfaces()) marks all ifaces inactive and removes and frees any that are not re-advertised via list_del() + kref_put(), where release_iface() is a bare kfree(). Since niface typically has no channel holding a reference, the list reference is its last and it can be freed inside the unlocked window. On continue, the iterator advance step then dereferences niface->iface_head.next, and the loop body reads iface->rdma_capable/is_active, both on freed memory. Fix this by never keeping an unreferenced list pointer across the unlocked window. Each channel attempt now re-scans the list from the head under iface_lock, takes a kref on the selected candidate, and passes only that referenced candidate to cifs_ses_add_channel(). weight_fulfilled still tracks selection progress, so restarting the scan preserves the original weighted distribution and the weight_fulfilled-before-kref_put ordering on the failure path. Add a per-pass attempts cap so a flapping interface refresh cannot keep the inner loop spinning within a single tries increment."
    },
    {
      "id": "CVE-2026-98172",
      "url": "https://spydr.io/cve/CVE-2026-98172",
      "published": "2026-10-06T09:17:58.920Z",
      "modified": "2026-10-06T09:17:58.920Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": 0.00172,
      "epss_percentile": 0.06045,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbd_connection leak on cifs_get_tcp_session() error When an RDMA connection is successfully established via smbd_get_connection() but cifs_get_tcp_session() later fails (e.g. kthread_create() returns an error), the error path frees tcp_ses without first destroying the smbd_connection. Fix this by calling smbd_destroy() in the out_err cleanup path before kfree(tcp_ses). smbd_destroy() safely handles the case where smbd_conn is NULL, so it can be called unconditionally."
    },
    {
      "id": "CVE-2026-98171",
      "url": "https://spydr.io/cve/CVE-2026-98171",
      "published": "2026-10-06T09:17:58.773Z",
      "modified": "2026-10-07T07:17:03.600Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.00506,
      "epss_percentile": 0.41274,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs Fix several related bounds checking and pointer lifecycle issues in receive_encrypted_standard()'s handling of compound encrypted frames: - Clear next_buffer after assigning it to server->bigbuf. A stale next_buffer pointer can lead to a use-after-free on subsequent error paths. - Update pdu_length to the decrypted plaintext size (buf_size). Using the pre-decryption length allows NextCommand to point into stale ciphertext residue. - Reject next_cmd values smaller than MID_HEADER_SIZE(server). - Fix an integer overflow in the upper bound check by verifying pdu_length - next_cmd < MID_HEADER_SIZE(server), ensuring the trailing slice is large enough for a header."
    },
    {
      "id": "CVE-2026-98170",
      "url": "https://spydr.io/cve/CVE-2026-98170",
      "published": "2026-10-06T09:17:58.640Z",
      "modified": "2026-10-06T09:17:58.640Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": 0.002,
      "epss_percentile": 0.08993,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() In move_smb2_ea_to_cifs(), the while (src_size > 0) loop condition is insufficient. It allows iteration to continue even if the remaining src_size is too small to contain a complete smb2_ea_info structure. Consequently, reads of ea_name_length and ea_value_length can occur out-of-bounds. Fix this by ensuring src_size >= sizeof(*src) before attempting to read any structure fields. Additionally, reject any next_entry_offset that is smaller than sizeof(*src) or that would advance the pointer beyond the available buffer. Note that for calls where the server returns a malformed EA list, the error returned to userspace changes from -ENODATA (getxattr) or -ERANGE (listxattr) to -EIO. This correctly signals a server protocol error rather than misleadingly indicating \"attribute not present\" or \"output buffer too small\"."
    },
    {
      "id": "CVE-2026-98169",
      "url": "https://spydr.io/cve/CVE-2026-98169",
      "published": "2026-10-06T09:17:58.480Z",
      "modified": "2026-10-07T07:17:03.450Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
      "score_source": "CNA",
      "epss": 0.00432,
      "epss_percentile": 0.35507,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOB read in smb3_enum_snapshots() If snapshot_array_size is smaller than GMT_TOKEN_SIZE, smb3_enum_snapshots() sets ret_data_len to sizeof(struct smb_snapshot_array) without verifying the actual length of the server's reply. Because SMB2_ioctl() places no lower bound on the server-supplied OutputCount and allocates retbuf to exactly that length, a short reply results in ret_data_len exceeding the size of retbuf. The subsequent copy_to_user() then reads past the end of retbuf, leaking adjacent slab memory to userspace. The subsequent clamp check is ineffective as it only reduces ret_data_len. Fix this by rejecting replies shorter than sizeof(struct smb_snapshot_array) with -EIO. Note that the bound is set to the 12-byte struct size rather than the 16-byte MIN_SNAPSHOT_ARRAY_SIZE defined in MS-SMB2 3.3.5.15.1, because 12 bytes is exactly what copy_to_user() attempts to read."
    },
    {
      "id": "CVE-2026-98168",
      "url": "https://spydr.io/cve/CVE-2026-98168",
      "published": "2026-10-06T09:17:58.333Z",
      "modified": "2026-10-06T09:17:58.333Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": 0.002,
      "epss_percentile": 0.08991,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix reparse buffer bounds in cifs_query_reparse_point() In cifs_query_reparse_point(), the start >= end check before casting to struct reparse_data_buffer * only ensures the start pointer is within the response. It fails to verify that there is enough space remaining for the fixed 8-byte header of the structure. If a server provides a DataOffset that leaves less than 8 bytes remaining, the check passes, but subsequent reads of ReparseTag and ReparseDataLength will occur out-of-bounds. Fix this by ensuring the remaining space is at least the size of the reparse_data_buffer structure before accessing its fields."
    },
    {
      "id": "CVE-2026-98167",
      "url": "https://spydr.io/cve/CVE-2026-98167",
      "published": "2026-10-06T09:17:58.177Z",
      "modified": "2026-10-06T09:17:58.177Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": 0.00216,
      "epss_percentile": 0.10991,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: smb: client: fix server->total_read for compound encrypted PDUs In receive_encrypted_standard(), server->total_read is left at the full decrypted frame size when walking sub-PDUs of a compound encrypted frame. As a result, cifs_handle_standard() passes this full size to smb2_check_message(), causing the PDU length guards to incorrectly validate the entire compound frame instead of the current sub-PDU. This allows truncated non-last sub-PDUs to bypass length validation, leading to out-of-bounds reads in smb2_get_data_area_len(). Fix this by setting server->total_read to the true length of the current sub-PDU: next_cmd for non-last sub-PDUs, and the remaining pdu_length for the last one."
    },
    {
      "id": "CVE-2026-98166",
      "url": "https://spydr.io/cve/CVE-2026-98166",
      "published": "2026-10-06T09:17:58.033Z",
      "modified": "2026-10-07T07:17:03.320Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.00154,
      "epss_percentile": 0.03945,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: drm/ttm: fix swapped-out resources never leaving their bulk_move range ttm_tt_swapout() returns the number of pages swapped out on success and a negative error code on failure; for a populated ttm it never returns zero. Commit b2ed01e7ad3d (\"drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure\") moved the bulk_move bookkeeping in ttm_bo_swapout_cb() under \"if (!ret)\", so the ttm_resource_del_bulk_move_unevictable() / ttm_resource_move_to_lru_tail() pair is now skipped on every successful swapout. The equivalent change for the shrinker in commit 1d59f36e95f7 (\"drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on backup failure\") tests \"lret > 0\", which is what was intended here as well. Before b2ed01e7ad3d the resource was taken off the bulk_move before the swapout; since then a swapped-out resource stays inside its BO's bulk_move range (and on the manager LRU) although it is unevictable. When it is later freed or the BO leaves the bulk_move (ttm_resource_free(), ttm_bo_set_bulk_move() via amdgpu_vm_bo_del()), ttm_resource_del_bulk_move() skips it because of its !ttm_resource_unevictable() guard, so a range endpoint in pos->first / pos->last is left pointing at freed memory. The next ttm_lru_bulk_move_tail() or ttm_resource_add_bulk_move() on that cursor is a use-after-free, seen as the resv WARN in ttm_lru_bulk_move_add(), \"list_del corruption\" in ttm_resource_move_to_lru_tail() or a NULL dereference in ttm_resource_manager_next() -- minutes to hours after a hibernation, or at process exit / reboot following one. Samuel Ainsworth's analysis of drm/amd issue 5387 (see Link) identified the dangling cursor; the missing removal at swapout time is the reason it dangles. Testing the condition for success restores the removal. On an AMD Phoenix APU (ASUS UM3406GA, gfx1103) running suspend-then-hibernate on a 7.0.y stable kernel carrying the backport (Ubuntu 7.0.0-31) the bug crashed 5 of 18 hibernation cycles; a function profile of one hibernation showed 336 ttm_tt_swapout() calls and zero ttm_resource_del_bulk_move_unevictable() calls. With this change the removal happens for every swapped-out resource and 12 further cycles were clean."
    },
    {
      "id": "CVE-2026-98165",
      "url": "https://spydr.io/cve/CVE-2026-98165",
      "published": "2026-10-06T09:17:57.887Z",
      "modified": "2026-10-06T09:17:57.887Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": 0.00155,
      "epss_percentile": 0.04092,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [],
      "description": "In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: restrict BAR0 fallback read to SR-IOV VFs only The BAR0 fallback read path was introduced as a workaround for SR-IOV VFs where the VRAM aperture is not available during early init. Restrict this workaround to only SR-IOV VFs where it's needed. (cherry picked from commit d8a0affd207c813bd063fa2c27786f449eaf92b8)"
    },
    {
      "id": "CVE-2026-97308",
      "url": "https://spydr.io/cve/CVE-2026-97308",
      "published": "2026-10-06T09:17:57.740Z",
      "modified": "2026-10-06T15:04:52.637Z",
      "score": 4.8,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00193,
      "epss_percentile": 0.08164,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "WebFactory"
      ],
      "products": [
        "WebFactory Login Lockdown"
      ],
      "cwes": [
        "CWE-290"
      ],
      "description": "Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions."
    },
    {
      "id": "CVE-2026-95594",
      "url": "https://spydr.io/cve/CVE-2026-95594",
      "published": "2026-10-06T09:17:57.577Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00236,
      "epss_percentile": 0.13418,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Cozy Vision Technologies Pvt. Ltd."
      ],
      "products": [
        "Cozy Vision Technologies Pvt. Ltd. SMS Alert Order Notifications"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions."
    },
    {
      "id": "CVE-2026-95526",
      "url": "https://spydr.io/cve/CVE-2026-95526",
      "published": "2026-10-06T09:17:57.430Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.3,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00229,
      "epss_percentile": 0.12561,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "RealMag777"
      ],
      "products": [
        "RealMag777 BEAR"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in BEAR <= 1.2.2 versions."
    },
    {
      "id": "CVE-2026-95105",
      "url": "https://spydr.io/cve/CVE-2026-95105",
      "published": "2026-10-06T09:17:57.200Z",
      "modified": "2026-10-06T15:03:59.427Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.00115,
      "epss_percentile": 0.01411,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "danielberkompas"
      ],
      "products": [
        "danielberkompas cloak"
      ],
      "cwes": [
        "CWE-649"
      ],
      "description": "Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with write access to stored ciphertext to make it decrypt to a chosen value via bit flipping. Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key tag, the IV and the ciphertext with no MAC. decrypt/2 checks only the key tag and the minimum length before it returns the plaintext, and Cloak.Ciphers.Deprecated.AES.CTR decrypts the legacy format the same way. CTR is a stream cipher, so a value XORed into the stored ciphertext is XORed into the plaintext at the same offset. An attacker who can write to the encrypted store (for example through SQL injection or a compromised replica) and who knows or can guess a stored plaintext can replace it with any value of the same length. The application receives that value with no error. This issue affects cloak: from 0.1.0-pre onward."
    },
    {
      "id": "CVE-2026-94675",
      "url": "https://spydr.io/cve/CVE-2026-94675",
      "published": "2026-10-06T09:17:57.047Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00191,
      "epss_percentile": 0.08035,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Fluent Forms Free vs Pro"
      ],
      "products": [
        "Fluent Forms Free vs Pro Fluent Forms Pro Add On Pack"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions."
    },
    {
      "id": "CVE-2026-94206",
      "url": "https://spydr.io/cve/CVE-2026-94206",
      "published": "2026-10-06T09:17:56.813Z",
      "modified": "2026-10-06T15:03:59.427Z",
      "score": 6.3,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.00256,
      "epss_percentile": 0.15778,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "danielberkompas"
      ],
      "products": [
        "danielberkompas cloak_ecto",
        "danielberkompas cloak"
      ],
      "cwes": [
        "CWE-916"
      ],
      "description": "Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured. The dump/1 callback that Cloak.Ecto.PBKDF2 (Cloak.Fields.PBKDF2 in cloak before the Ecto code moved to cloak_ecto) injects into a field module calls :pbkdf2.pbkdf2/4 with config[:size] in the iteration-count position. The :iterations setting is validated but never used. With the cloak_ecto defaults (iterations: 600_000, size: 32) each hash runs 32 PBKDF2 rounds instead of 600,000, so offline guessing of values such as email addresses costs about 18,750 times less than configured. This issue affects cloak_ecto: from 1.0.0-alpha.0 onward; cloak: from 0.7.0 before 1.0.0-alpha.0."
    },
    {
      "id": "CVE-2026-66588",
      "url": "https://spydr.io/cve/CVE-2026-66588",
      "published": "2026-10-06T09:17:56.660Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00299,
      "epss_percentile": 0.2073,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Dream-Theme"
      ],
      "products": [
        "Dream-Theme The7"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in The7 <= 14.2.2 versions."
    },
    {
      "id": "CVE-2026-62072",
      "url": "https://spydr.io/cve/CVE-2026-62072",
      "published": "2026-10-06T09:17:56.500Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00338,
      "epss_percentile": 0.25182,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Progress Planner"
      ],
      "products": [
        "Progress Planner"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions."
    },
    {
      "id": "CVE-2026-4889",
      "url": "https://spydr.io/cve/CVE-2026-4889",
      "published": "2026-10-06T09:17:56.317Z",
      "modified": "2026-10-06T15:18:12.170Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "incibe.es",
      "epss": 0.00299,
      "epss_percentile": 0.20731,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "RDL Technologies"
      ],
      "products": [
        "RDL Technologies eLoanApp Platform"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries."
    },
    {
      "id": "CVE-2026-48199",
      "url": "https://spydr.io/cve/CVE-2026-48199",
      "published": "2026-10-06T09:17:55.930Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00394,
      "epss_percentile": 0.31411,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Beplusthemes"
      ],
      "products": [
        "Beplusthemes Sermon'e"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions."
    },
    {
      "id": "CVE-2026-48197",
      "url": "https://spydr.io/cve/CVE-2026-48197",
      "published": "2026-10-06T09:17:55.777Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00462,
      "epss_percentile": 0.3803,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "PublishPress"
      ],
      "products": [
        "PublishPress Capabilities"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
