{
  "query": {
    "page": "7"
  },
  "count": 20,
  "total": 46359,
  "page": 7,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T02:45:17.993Z",
    "kev": "2026-10-06T03:44:20.273Z",
    "epss": "2026-10-06T00:57:13.818Z",
    "breaches": "2026-10-06T00:45:13.561Z",
    "posts": "2026-10-06T03:45:20.784Z"
  },
  "links": {
    "web": "https://spydr.io/threats?page=7",
    "next": "https://spydr.io/threats.json?page=8"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2026-105392",
      "url": "https://spydr.io/cve/CVE-2026-105392",
      "published": "2026-10-05T20:17:10.827Z",
      "modified": "2026-10-05T20:17:10.827Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Lybbn"
      ],
      "products": [
        "Lybbn Django-Vue-Lyadmin"
      ],
      "cwes": [
        "CWE-320",
        "CWE-321"
      ],
      "description": "A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: \"The issue with this key is described in the documentation. Developers need to manually change their keys before deployment.\""
    },
    {
      "id": "CVE-2026-105389",
      "url": "https://spydr.io/cve/CVE-2026-105389",
      "published": "2026-10-05T20:17:10.610Z",
      "modified": "2026-10-05T20:17:10.610Z",
      "score": 2.1,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "feelec-yishu"
      ],
      "products": [
        "feelec-yishu feelcrm-os"
      ],
      "cwes": [
        "CWE-284",
        "CWE-434"
      ],
      "description": "A security vulnerability has been detected in feelec-yishu feelcrm-os 1.0.0. This issue affects some unknown processing of the file App/Feelcrm/Crm/Controller/UploadController.class.php of the component UploadTicketFile Endpoint. Such manipulation of the argument cmd leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-105388",
      "url": "https://spydr.io/cve/CVE-2026-105388",
      "published": "2026-10-05T20:17:10.393Z",
      "modified": "2026-10-05T20:17:10.393Z",
      "score": 2.1,
      "severity": "low",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "feelec-yishu"
      ],
      "products": [
        "feelec-yishu feelcrm-os"
      ],
      "cwes": [
        "CWE-74",
        "CWE-89"
      ],
      "description": "A weakness has been identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function index of the file App/Feelcrm/Index/Controller/MemberController.class.php of the component Member Endpoint. This manipulation of the argument group_id causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."
    },
    {
      "id": "CVE-2026-104030",
      "url": "https://spydr.io/cve/CVE-2026-104030",
      "published": "2026-10-05T20:17:08.637Z",
      "modified": "2026-10-05T20:17:08.637Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "redhat.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Red Hat"
      ],
      "products": [
        "Red Hat Enterprise Linux 10",
        "Red Hat Enterprise Linux 6",
        "Red Hat Enterprise Linux 7",
        "Red Hat Enterprise Linux 8",
        "Red Hat Enterprise Linux 9",
        "Red Hat OpenShift Container Platform 4"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "A flaw was found in sssd. This vulnerability allows a local user to cause a Denial of Service (DoS) by submitting a specially crafted passkey authentication token that lacks null terminators. The authentication service reads past the end of the provided memory buffer, causing the process to crash and disrupting authentication services."
    },
    {
      "id": "CVE-2026-104029",
      "url": "https://spydr.io/cve/CVE-2026-104029",
      "published": "2026-10-05T20:17:08.487Z",
      "modified": "2026-10-05T20:17:08.487Z",
      "score": 3.3,
      "severity": "low",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "score_source": "redhat.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Red Hat"
      ],
      "products": [
        "Red Hat Enterprise Linux 10",
        "Red Hat Enterprise Linux 6",
        "Red Hat Enterprise Linux 7",
        "Red Hat Enterprise Linux 8",
        "Red Hat Enterprise Linux 9",
        "Red Hat OpenShift Container Platform 4"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "A flaw was found in SSSD. A local attacker can exploit this vulnerability by sending a specially crafted request to the autofs responder UNIX socket. Due to improper buffer offset calculation during request parsing, the service performs an out-of-bounds memory read. This flaw can cause the autofs responder process to crash, resulting in a denial of service (DoS)."
    },
    {
      "id": "CVE-2026-103348",
      "url": "https://spydr.io/cve/CVE-2026-103348",
      "published": "2026-10-05T20:17:08.330Z",
      "modified": "2026-10-05T20:17:08.330Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Smackcoders Inc."
      ],
      "products": [
        "Smackcoders Inc. WP Ultimate Exporter"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0."
    },
    {
      "id": "CVE-2026-103337",
      "url": "https://spydr.io/cve/CVE-2026-103337",
      "published": "2026-10-05T20:17:08.177Z",
      "modified": "2026-10-05T20:17:08.177Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Kirillbdev"
      ],
      "products": [
        "Kirillbdev WC Ukraine Shipping"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through 1.23.2."
    },
    {
      "id": "CVE-2026-103066",
      "url": "https://spydr.io/cve/CVE-2026-103066",
      "published": "2026-10-05T20:17:08.027Z",
      "modified": "2026-10-05T20:17:08.027Z",
      "score": 8.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "WP BASE"
      ],
      "products": [
        "WP BASE Booking"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0."
    },
    {
      "id": "CVE-2026-100511",
      "url": "https://spydr.io/cve/CVE-2026-100511",
      "published": "2026-10-05T20:17:07.177Z",
      "modified": "2026-10-05T20:17:07.177Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Vektor Inc."
      ],
      "products": [
        "Vektor Inc. VK Google Job Posting Manager"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1."
    },
    {
      "id": "CVE-2026-100506",
      "url": "https://spydr.io/cve/CVE-2026-100506",
      "published": "2026-10-05T20:17:03.760Z",
      "modified": "2026-10-05T20:17:03.760Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "WP Spell Check"
      ],
      "products": [
        "WP Spell Check"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1."
    },
    {
      "id": "CVE-2026-97309",
      "url": "https://spydr.io/cve/CVE-2026-97309",
      "published": "2026-10-05T19:17:27.667Z",
      "modified": "2026-10-05T19:17:27.667Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Webful Creations"
      ],
      "products": [
        "Webful Creations RepairBuddy"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through 4.1226."
    },
    {
      "id": "CVE-2026-97305",
      "url": "https://spydr.io/cve/CVE-2026-97305",
      "published": "2026-10-05T19:17:27.527Z",
      "modified": "2026-10-05T19:17:27.527Z",
      "score": 6.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Themeisle"
      ],
      "products": [
        "Themeisle AI Chatbot for WordPress – Hyve Lite"
      ],
      "cwes": [
        "CWE-639"
      ],
      "description": "Authorization Bypass Through User-Controlled Key vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Chatbot for WordPress – Hyve Lite: from n/a through 2.0.2."
    },
    {
      "id": "CVE-2026-97304",
      "url": "https://spydr.io/cve/CVE-2026-97304",
      "published": "2026-10-05T19:17:27.390Z",
      "modified": "2026-10-05T19:17:27.390Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Arraytics"
      ],
      "products": [
        "Arraytics Timetics"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.63."
    },
    {
      "id": "CVE-2026-97303",
      "url": "https://spydr.io/cve/CVE-2026-97303",
      "published": "2026-10-05T19:17:27.267Z",
      "modified": "2026-10-05T19:17:27.267Z",
      "score": 7.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "Apps Mav"
      ],
      "products": [
        "Apps Mav Scratch & Win – Giveaways and Contests"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaways and Contests: from n/a through 3.0.2."
    },
    {
      "id": "CVE-2026-97283",
      "url": "https://spydr.io/cve/CVE-2026-97283",
      "published": "2026-10-05T19:17:27.133Z",
      "modified": "2026-10-05T19:17:27.133Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "Liquid Web / StellarWP"
      ],
      "products": [
        "Liquid Web / StellarWP Advanced Post Manager"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5."
    },
    {
      "id": "CVE-2026-97275",
      "url": "https://spydr.io/cve/CVE-2026-97275",
      "published": "2026-10-05T19:17:26.890Z",
      "modified": "2026-10-05T19:17:26.890Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [
        "VillaTheme"
      ],
      "products": [
        "VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder"
      ],
      "cwes": [
        "CWE-1284"
      ],
      "description": "Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Input Data Manipulation.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28."
    },
    {
      "id": "CVE-2026-97070",
      "url": "https://spydr.io/cve/CVE-2026-97070",
      "published": "2026-10-05T19:17:26.750Z",
      "modified": "2026-10-05T19:17:26.750Z",
      "score": 6.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "patchstack.com",
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": "none",
      "vendors": [
        "CozyThemes"
      ],
      "products": [
        "CozyThemes Cozy Blocks"
      ],
      "cwes": [
        "CWE-639"
      ],
      "description": "Authorization Bypass Through User-Controlled Key vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cozy Blocks: from n/a through 2.2.23."
    },
    {
      "id": "CVE-2026-95166",
      "url": "https://spydr.io/cve/CVE-2026-95166",
      "published": "2026-10-05T19:17:26.640Z",
      "modified": "2026-10-05T19:17:26.640Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [],
      "products": [],
      "cwes": [],
      "description": "In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload."
    },
    {
      "id": "CVE-2026-95165",
      "url": "https://spydr.io/cve/CVE-2026-95165",
      "published": "2026-10-05T19:17:26.517Z",
      "modified": "2026-10-05T19:17:26.517Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [],
      "products": [],
      "cwes": [],
      "description": "Bacularis 5.4.0 - 6.5.1 is vulnerable to Cross Site Scripting (XSS) in the Organization name field."
    },
    {
      "id": "CVE-2026-88424",
      "url": "https://spydr.io/cve/CVE-2026-88424",
      "published": "2026-10-05T19:17:26.053Z",
      "modified": "2026-10-05T19:17:26.053Z",
      "score": null,
      "severity": null,
      "cvss_version": null,
      "vector": null,
      "score_source": null,
      "epss": null,
      "epss_percentile": null,
      "exploited": false,
      "kev": null,
      "ssvc_exploitation": null,
      "vendors": [],
      "products": [],
      "cwes": [],
      "description": "FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability allows attackers to access sensitive database information via crafted SQL statements."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
