{
  "query": {
    "page": "59"
  },
  "count": 20,
  "total": 47696,
  "page": 59,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T02:48:45.529Z",
    "kev": "2026-10-08T02:49:45.513Z",
    "epss": "2026-10-08T01:00:40.923Z",
    "breaches": "2026-10-08T00:48:40.536Z",
    "posts": "2026-10-08T02:48:45.528Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=59",
    "next": "https://spydr.io/threats.json?page=60"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-95526",
      "url": "https://spydr.io/cve/CVE-2026-95526",
      "published": "2026-10-06T09:17:57.430Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.3,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00229,
      "epss_percentile": 0.12561,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "RealMag777"
      ],
      "products": [
        "RealMag777 BEAR"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in BEAR <= 1.2.2 versions."
    },
    {
      "id": "CVE-2026-95105",
      "url": "https://spydr.io/cve/CVE-2026-95105",
      "published": "2026-10-06T09:17:57.200Z",
      "modified": "2026-10-06T15:03:59.427Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.00115,
      "epss_percentile": 0.01411,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "danielberkompas"
      ],
      "products": [
        "danielberkompas cloak"
      ],
      "cwes": [
        "CWE-649"
      ],
      "description": "Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with write access to stored ciphertext to make it decrypt to a chosen value via bit flipping. Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key tag, the IV and the ciphertext with no MAC. decrypt/2 checks only the key tag and the minimum length before it returns the plaintext, and Cloak.Ciphers.Deprecated.AES.CTR decrypts the legacy format the same way. CTR is a stream cipher, so a value XORed into the stored ciphertext is XORed into the plaintext at the same offset. An attacker who can write to the encrypted store (for example through SQL injection or a compromised replica) and who knows or can guess a stored plaintext can replace it with any value of the same length. The application receives that value with no error. This issue affects cloak: from 0.1.0-pre onward."
    },
    {
      "id": "CVE-2026-94675",
      "url": "https://spydr.io/cve/CVE-2026-94675",
      "published": "2026-10-06T09:17:57.047Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00191,
      "epss_percentile": 0.08035,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Fluent Forms Free vs Pro"
      ],
      "products": [
        "Fluent Forms Free vs Pro Fluent Forms Pro Add On Pack"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions."
    },
    {
      "id": "CVE-2026-94206",
      "url": "https://spydr.io/cve/CVE-2026-94206",
      "published": "2026-10-06T09:17:56.813Z",
      "modified": "2026-10-06T15:03:59.427Z",
      "score": 6.3,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.00256,
      "epss_percentile": 0.15778,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "poc",
      "vendors": [
        "danielberkompas"
      ],
      "products": [
        "danielberkompas cloak_ecto",
        "danielberkompas cloak"
      ],
      "cwes": [
        "CWE-916"
      ],
      "description": "Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured. The dump/1 callback that Cloak.Ecto.PBKDF2 (Cloak.Fields.PBKDF2 in cloak before the Ecto code moved to cloak_ecto) injects into a field module calls :pbkdf2.pbkdf2/4 with config[:size] in the iteration-count position. The :iterations setting is validated but never used. With the cloak_ecto defaults (iterations: 600_000, size: 32) each hash runs 32 PBKDF2 rounds instead of 600,000, so offline guessing of values such as email addresses costs about 18,750 times less than configured. This issue affects cloak_ecto: from 1.0.0-alpha.0 onward; cloak: from 0.7.0 before 1.0.0-alpha.0."
    },
    {
      "id": "CVE-2026-66588",
      "url": "https://spydr.io/cve/CVE-2026-66588",
      "published": "2026-10-06T09:17:56.660Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00299,
      "epss_percentile": 0.2073,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Dream-Theme"
      ],
      "products": [
        "Dream-Theme The7"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in The7 <= 14.2.2 versions."
    },
    {
      "id": "CVE-2026-62072",
      "url": "https://spydr.io/cve/CVE-2026-62072",
      "published": "2026-10-06T09:17:56.500Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00338,
      "epss_percentile": 0.25182,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Progress Planner"
      ],
      "products": [
        "Progress Planner"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions."
    },
    {
      "id": "CVE-2026-4889",
      "url": "https://spydr.io/cve/CVE-2026-4889",
      "published": "2026-10-06T09:17:56.317Z",
      "modified": "2026-10-06T15:18:12.170Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "incibe.es",
      "epss": 0.00299,
      "epss_percentile": 0.20731,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "RDL Technologies"
      ],
      "products": [
        "RDL Technologies eLoanApp Platform"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries."
    },
    {
      "id": "CVE-2026-48199",
      "url": "https://spydr.io/cve/CVE-2026-48199",
      "published": "2026-10-06T09:17:55.930Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00394,
      "epss_percentile": 0.31411,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Beplusthemes"
      ],
      "products": [
        "Beplusthemes Sermon'e"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions."
    },
    {
      "id": "CVE-2026-48197",
      "url": "https://spydr.io/cve/CVE-2026-48197",
      "published": "2026-10-06T09:17:55.777Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": 0.00462,
      "epss_percentile": 0.3803,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "PublishPress"
      ],
      "products": [
        "PublishPress Capabilities"
      ],
      "cwes": [
        "CWE-266"
      ],
      "description": "Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0."
    },
    {
      "id": "CVE-2026-42638",
      "url": "https://spydr.io/cve/CVE-2026-42638",
      "published": "2026-10-06T09:17:55.627Z",
      "modified": "2026-10-07T08:16:57.320Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00263,
      "epss_percentile": 0.16687,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Awesomemotive"
      ],
      "products": [
        "Awesomemotive Easy Digital Downloads"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Missing Authorization vulnerability in Awesomemotive Easy Digital Downloads easy-digital-downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.7.1."
    },
    {
      "id": "CVE-2026-42637",
      "url": "https://spydr.io/cve/CVE-2026-42637",
      "published": "2026-10-06T09:17:55.480Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00332,
      "epss_percentile": 0.24356,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Payplug"
      ],
      "products": [
        "PayPlug for WooCommerce (Official)"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions."
    },
    {
      "id": "CVE-2026-42636",
      "url": "https://spydr.io/cve/CVE-2026-42636",
      "published": "2026-10-06T09:17:55.333Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00251,
      "epss_percentile": 0.15139,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "WP Legal Pages"
      ],
      "products": [
        "WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6 versions."
    },
    {
      "id": "CVE-2026-42635",
      "url": "https://spydr.io/cve/CVE-2026-42635",
      "published": "2026-10-06T09:17:55.193Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00251,
      "epss_percentile": 0.15139,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "wpgenie"
      ],
      "products": [
        "wpgenie WooCommerce Simple Auctions"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions."
    },
    {
      "id": "CVE-2026-42634",
      "url": "https://spydr.io/cve/CVE-2026-42634",
      "published": "2026-10-06T09:17:55.047Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00251,
      "epss_percentile": 0.15139,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "bPlugins"
      ],
      "products": [
        "bPlugins Video Background Block – Use video as background in the section."
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions."
    },
    {
      "id": "CVE-2026-42418",
      "url": "https://spydr.io/cve/CVE-2026-42418",
      "published": "2026-10-06T09:17:54.900Z",
      "modified": "2026-10-07T08:16:57.203Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00251,
      "epss_percentile": 0.15143,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Socialrocket"
      ],
      "products": [
        "Socialrocket Social Rocket"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Socialrocket Social Rocket social-rocket allows Reflected XSS.This issue affects Social Rocket: from n/a through 1.3.5."
    },
    {
      "id": "CVE-2026-42417",
      "url": "https://spydr.io/cve/CVE-2026-42417",
      "published": "2026-10-06T09:17:54.757Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00325,
      "epss_percentile": 0.2348,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "reputeinfosystems"
      ],
      "products": [
        "reputeinfosystems ARMember Premium"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions."
    },
    {
      "id": "CVE-2026-42416",
      "url": "https://spydr.io/cve/CVE-2026-42416",
      "published": "2026-10-06T09:17:54.610Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 8.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": 0.0029,
      "epss_percentile": 0.1973,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "AndonDesign"
      ],
      "products": [
        "AndonDesign UDesign Core"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Subscriber SQL Injection in UDesign Core <= 4.15.0 versions."
    },
    {
      "id": "CVE-2026-42415",
      "url": "https://spydr.io/cve/CVE-2026-42415",
      "published": "2026-10-06T09:17:54.463Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": 0.00247,
      "epss_percentile": 0.14631,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "p-themes"
      ],
      "products": [
        "p-themes Porto Theme - Functionality"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions."
    },
    {
      "id": "CVE-2026-42414",
      "url": "https://spydr.io/cve/CVE-2026-42414",
      "published": "2026-10-06T09:17:54.320Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 8.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": 0.0029,
      "epss_percentile": 0.1973,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "CridioStudio"
      ],
      "products": [
        "CridioStudio ListingPro"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Subscriber SQL Injection in ListingPro <= 2.9.12 versions."
    },
    {
      "id": "CVE-2026-42413",
      "url": "https://spydr.io/cve/CVE-2026-42413",
      "published": "2026-10-06T09:17:54.170Z",
      "modified": "2026-10-06T15:04:25.990Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "patchstack.com",
      "epss": 0.00316,
      "epss_percentile": 0.22485,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "DaftPlug"
      ],
      "products": [
        "DaftPlug Snapshotify &#8211; All-in-One Backup &amp; Restore &amp; Migrate"
      ],
      "cwes": [
        "CWE-201"
      ],
      "description": "Unauthenticated Sensitive Data Exposure in Snapshotify &#8211; All-in-One Backup &amp; Restore &amp; Migrate <= 1.3.2 versions."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
